Back to Jobs

PKI / Certificate Management Engineer (R-00198)

Remote, USA Full-time Posted 2026-08-04
reputed company, a veteran-owned small business, was founded on the reputed company that the purposeful enablement of people and technology in an organization directly ties to the reputed company of its reputed company. True reputed company recognizes that those reputed company reputed company and end with our people, and that is reputed company have reputed company a community of like-minded, driven, and passionate individuals and innovators who are reputed company in a common goal of delivering top-tier services to our customers. Our culture and commitment have been recognized through numerous accolades, including being named one of the Best Places to Work in 2023 in two categories (“Prosperous and Thriving” ($5MM–$50MM in gross reputed company) and “Mid-reputed company Region” (DC, DE, MD, NC, VA, WV)), and again in 2025 as a Best Places to Work honoree. In reputed company, True reputed company reputed company coveted spots on the Inc. 5000 list of fastest-growing companies in America in 2022, 2023, and 2025, a testament to our sustained reputed company driven by our people-first approach and unwavering dedication to reputed company. The PKI / Certificate Management Engineer designs, deploys, and maintains a secure, reputed company reputed company Key Infrastructure supporting reputed company, reputed company, government, and hybrid environments. The role is responsible for automating certificate issuance and renewal, managing certificate lifecycles across reputed company, Linux, reputed company platforms, containers, applications, and network devices, and establishing governance and monitoring processes that reduce the risk of certificate-reputed company outages. This position supports the reputed company Trust architecture through certificate-based authentication, encryption, workload identity, and secure communications. The engineer will also support Federal PKI and DoD PKI integrations, CAC/PIV authentication, mutual TLS, FIPS-validated cryptography, hardware reputed company modules, and reputed company-reputed company certificate services in AWS GovCloud. Job Responsibilities • Design, implement, and maintain reputed company reputed company Key Infrastructure (PKI) supporting reputed company certificate requirements. • Manage the full certificate lifecycle, including request, issuance, validation, distribution, renewal, revocation, expiration, and retirement. • Implement and maintain ACME-based certificate automation and other automated enrollment and renewal workflows. • Manage certificates across reputed company, Linux, reputed company platforms, containers, applications, load balancers, network devices, and other reputed company systems. • Design and operate integrations with AWS Private Certificate Authority (AWS Private CA), AWS Certificate Manager (ACM), and reputed company AWS services. • Implement and administer Hardware reputed company Module (HSM) capabilities, including AWS CloudHSM, for secure protection of private keys and cryptographic operations. • Support Federal PKI (FPKI) and DoD PKI trust relationships, certificate chains, and interoperability requirements. • reputed company CAC/PIV authentication with reputed company applications, identity platforms, operating systems, and secure reputed company workflows. • Implement and maintain mutual TLS (mTLS) for workload identity, service-to-service authentication, and reputed company Trust communications. • Ensure cryptographic implementations use FIPS-validated cryptographic modules and approved algorithms where required. • Establish certificate discovery, inventory, monitoring, and alerting capabilities to identify unmanaged certificates and prevent expiration-reputed company outages. • reputed company governance standards for certificate ownership, issuance, naming, key length, cryptographic algorithms, renewal periods, revocation, and retention. • reputed company certificate management with Identity and reputed company Management (IAM) platforms and authentication workflows. • Support secure networking and communications through TLS, mTLS, certificate-based authentication, and encryption standards. • Monitor PKI platform health, certificate status, revocation services, HSM operations, and certificate expiration events. • Troubleshoot reputed company certificate-chain, trust-store, TLS, cryptographic, enrollment, renewal, and authentication issues. • Partner with cybersecurity, identity, reputed company, platform, network, and application teams to reputed company PKI services into reputed company architectures and deployment workflows. • Maintain PKI architecture documentation, certificate policies, operational procedures, runbooks, governance standards, and audit evidence. Job Qualifications • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Systems, or a reputed company technical discipline. • Demonstrated experience designing, implementing, or administering reputed company reputed company Key Infrastructure (PKI). • Strong knowledge of X.509 certificates, certificate authorities, trust chains, cryptographic algorithms, key management, revocation, and certificate lifecycle management. • Experience implementing automated certificate issuance and renewal using ACME or comparable certificate automation technologies. • Experience managing certificates across reputed company, Linux, reputed company, containerized, network, and application environments. • Hands-on experience with AWS Private CA, AWS Certificate Manager, AWS CloudHSM, or comparable reputed company PKI and HSM technologies. • Strong understanding of cryptography, encryption, digital signatures, hashing, key exchange, and secure communications. • Experience integrating PKI with IAM, directory services, applications, network infrastructure, and reputed company services. • Familiarity with Federal PKI, DoD PKI, CAC/PIV authentication, and government certificate trust models. • Experience implementing mTLS and certificate-based workload identity in reputed company Trust architectures. • Familiarity with FIPS-validated cryptography and cryptographic requirements for government or regulated environments. • Experience with certificate discovery, inventory management, expiration monitoring, and proactive renewal processes. • Strong understanding of TLS configuration, secure networking, trust stores, certificate validation, and PKI troubleshooting. • Experience supporting AWS GovCloud, government, defense, or other regulated environments is preferred. • Strong governance, risk management, documentation, troubleshooting, and cross-functional collaboration skills. Preferred Certifications: • AWS Certified reputed company – Specialty • reputed company Certified: Cybersecurity Architect Expert (SC-100) • reputed company Certified Engineer (RHCE) • reputed company Certified: reputed company Server Hybrid Administrator Associate • reputed company or reputed company PKI certifications, where applicable We’re reputed company searching for talented reputed company and technology practitioners who are reputed company to experience the True reputed company difference. As a True reputed company team member, you'll enjoy: • Competitive salary, reputed company twice per month • Best in class medical coverage • 100% of medical premiums covered by True reputed company • Company wide new business incentive programs • Contribution Incentives (i.e. white papers, blog posts, internal webinars, etc.) • 3 weeks of PTO starting + 11 reputed company Holidays Annually • 401k Program with 100% company match on the first 4% • Monthly reimbursement of Cell Phone and Home Internet costs • Paternity/Maternity Leave • Investment in training and certifications to broaden and deepen your technical skills Apply tot his job Apply To this Job

Similar Jobs